
frida-c2-mcp
Agentic C2-style MCP server for Frida instrumentation on rooted Android and jailbroken iOS.

Agentic C2-style MCP server for Frida instrumentation on rooted Android and jailbroken iOS.

LSTAR - CobaltStrike Translated to EN

Salsa Tools - ShellReverse TCP/UDP/ICMP/DNS/SSL/BINDTCP/Shellcode/SILENTTRINITY and AV bypass, AMSI patched

A technique of hiding malicious shellcode via Shannon encoding.

Chaining Havoc C2 SSRF with RCE to get reverse shell on Havoc C2 Server.

Modification of Metasploit module for RCE in Ruby-On-Rails Console CVE-2015-3224

Exploit for remote command execution in Golang go get command.

PHP script and guide for injecting PHP webshells into JPEG images using Jhead. Used to bypass file upload filters and achieve remote command…

CLI wrapper for MSFvenom that streamlines payload creation with profile management, automated listener generation, and organized output for…

CLI to generate PHP filter chains for remote code execution via controlled include/require parameters. Produces complex iconv-based filter bypasses…

Kautilya - Tool for easy use of Human Interface Devices for offensive security and penetration testing.

Yet another shellcode runner consists of different techniques for evaluating detection capabilities of endpoint security solutions

Malicious Maven pom.xml that uses "groovy-maven-plugin" to get RCE

Python codes of my blog.

Heap OOB write in MariaDB JSON_SCHEMA_VALID() → persistent privilege escalation (lab-assisted)

Lab vulnerável (Docker) + PoC Python para a CVE-2026-87902 — path traversal não autenticado no WordPress Core (page-template -> LFI -> RCE…

Malleable C2 profiles for Cobalt Strike

Python PoC exploiting CVE-2026-87902, an unauthenticated path traversal in WordPress locate_template() leading to LFI and PEAR-based RCE, with safe…